
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
@line/liff-common-profile-plugin
Advanced tools
A LIFF Plugin to get and auto-fill forms _common profile data_ from Account Center.
A LIFF Plugin to get and auto-fill forms common profile data from Account Center.
CDN versions of packages is hosted in TBD and can be imported using the script tag as shown below.
index.html
<html lang="en">
<head>
<meta charset="UTF-8" />
<link rel="icon" href="/src/favicon.ico" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<script src="TBD"></script>
<title>LIFF App</title>
</head>
<body>
<div id="root"></div>
<script type="module" src="/index.js"></script>
</body>
</html>
The package is then defined in the global object with the name liffCommonProfile
.
So you can use the package as a LIFF Plugin as follows in the js/ts file.
index.js
liff.use(new liffCommonProfile.LiffCommonProfilePlugin());
await liff.init({ liffId: "xxx" });
const profile = await liff.$commonProfile.get();
liff.$commonProfile.fill(profile);
npm install @line/liff-common-profile-plugin
import { LiffCommonProfilePlugin } from "@line/liff-common-profile-plugin";
liff.use(new LiffCommonProfilePlugin());
await liff.init({ liffId: "xxx" });
const profile = await liff.$commonProfile.get();
liff.$commonProfile.fill(profile);
FAQs
A LIFF Plugin to get and auto-fill forms _common profile data_ from Account Center.
We found that @line/liff-common-profile-plugin demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.